CVE-2025-41404: Irohasoft Iroha Board

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.

Affected products

  • Irohasoft Iroha Board: before 0.10.13 (fixed in 0.10.13)

Published 2025-06-26. Last modified 2026-06-17.